Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Update Services > ForeFront Client Security

Reply
Thread Tools Display Modes

ForeFront Client Security

 
 
Sawyer
Guest
Posts: n/a

 
      07-24-2009
Hello

I am running WSUS 3.0 sp1 on Windows 2008. Currently we are using WSUS to
push patches out to all of our servers, and we are using group policy to
deploy patches. The GPO is set to 3 "auto download and notify for install"
We manually go into WSUS and approve the patches that we want the servers to
get by approving them for a particular group. In WSUS we seperate servers
into group and these groups match the OU name the servers are in. We now
have installed Forefront client security and the servers will be getting the
client from WSUS. When i force the server to check in with the WSUS server
to force the FFC install the server will notify the admin on the box that an
update is available for install, and this is the problem i am running into.
We have 800 servers, and it would take months if admins had to manually log
onto the server and manually install the FFC, i know i can automatically
approve updates, and i have, but this setting doesnt automatically install
the FFC, it only automatically installes the updates for the client.

How can i get the main FFC to be automatically installed, and at the same
time all other security and critical updates need to be manually approved in
WSUS and the server notifys the admin for install? I cant create multiple
GPO's one gpo is set to 3 and is meant for manual approval in WSUS, and
another GPO is set to 4, because in WSUS as far as i know machines cant be
members of multiple groups.

Thanks for any help on this

 
Reply With Quote
 
 
 
 
Lawrence Garvin [MVP]
Guest
Posts: n/a

 
      07-24-2009
"Sawyer" <> wrote in message
news:B29CD704-19EA-4C64-908F-...

> When i force the server to check in with the WSUS server to force the FFC
> install the server will notify the admin on the box that an update is
> available for install, and this is the problem i am running into. We have
> 800 servers, and it would take months if admins had to manually log onto
> the server and manually install the FFC, i know i can automatically
> approve updates, and i have, but this setting doesnt automatically install
> the FFC, it only automatically installes the updates for the client.


> How can i get the main FFC to be automatically installed, and at the same
> time all other security and critical updates need to be manually approved
> in WSUS and the server notifys the admin for install?


Set an *expired* deadline on the Forefront Client package, and the Forefront
Client will be installed immediately upon detection (be careful about
required system restarts).

> because in WSUS as far as i know machines cant be members of multiple
> groups.


Actually they *can* be members of multiple WSUS target groups, but multiple
group memberships won't solve this problem. The machine can still only have
one composite policy configuration applied, and only one AUOptions value
active -- so your conclusion is valid, even though your reasoning is
incorrect.


--
Lawrence Garvin, M.S., MCITP:EA, MCDBA
Principal/CTO, Onsite Technology Solutions, Houston, Texas
Microsoft MVP - Software Distribution (2005-2009)

MS WSUS Website: http://www.microsoft.com/wsus
My MVP Profile: http://mvp.support.microsoft.com/pro...awrence.Garvin

 
Reply With Quote
 
Sawyer
Guest
Posts: n/a

 
      07-24-2009
Briliant recomendation this should do the trick. As far as i know the FFC
doesnt require a restart even when automatically installed, so i should be
ok with this, but i will have to test this out in a lab to make sure. Thanks
again!
"Lawrence Garvin [MVP]" <> wrote in message
news:...
> "Sawyer" <> wrote in message
> news:B29CD704-19EA-4C64-908F-...
>
>> When i force the server to check in with the WSUS server to force the FFC
>> install the server will notify the admin on the box that an update is
>> available for install, and this is the problem i am running into. We have
>> 800 servers, and it would take months if admins had to manually log onto
>> the server and manually install the FFC, i know i can automatically
>> approve updates, and i have, but this setting doesnt automatically
>> install the FFC, it only automatically installes the updates for the
>> client.

>
>> How can i get the main FFC to be automatically installed, and at the same
>> time all other security and critical updates need to be manually approved
>> in WSUS and the server notifys the admin for install?

>
> Set an *expired* deadline on the Forefront Client package, and the
> Forefront Client will be installed immediately upon detection (be careful
> about required system restarts).
>
>> because in WSUS as far as i know machines cant be members of multiple
>> groups.

>
> Actually they *can* be members of multiple WSUS target groups, but
> multiple group memberships won't solve this problem. The machine can still
> only have one composite policy configuration applied, and only one
> AUOptions value active -- so your conclusion is valid, even though your
> reasoning is incorrect.
>
>
> --
> Lawrence Garvin, M.S., MCITP:EA, MCDBA
> Principal/CTO, Onsite Technology Solutions, Houston, Texas
> Microsoft MVP - Software Distribution (2005-2009)
>
> MS WSUS Website: http://www.microsoft.com/wsus
> My MVP Profile: http://mvp.support.microsoft.com/pro...awrence.Garvin
>


 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Forefront Client Security on SBS 2008 Simon Thomson Windows Small Business Server 2 11-25-2009 08:06 AM
Forefront Client Security on SBS 2008 Premium Martyn Hudson Windows Small Business Server 1 03-17-2009 03:34 PM
Need help in deployment of ForeFront Client Security Kamran Khan Windows Vista Security 3 07-23-2008 12:15 PM
Forefront Client Security on SBS R2 Roman Windows Small Business Server 6 12-02-2007 08:34 AM
Microsoft Forefront Client Security on SBS 2003 R2 Manuel Amaral Windows Small Business Server 4 11-05-2007 05:24 AM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59